Impact
The vulnerability is an improper neutralization of input during web page generation in the RJ Quickcharts plugin, leading to a stored cross‑site scripting (XSS) flaw (CWE‑79). A malicious script can be embedded in chart data and later executed in the browsers of visitors who view the chart, potentially compromising their session or allowing arbitrary script execution within the site’s context.
Affected Systems
WordPress installations using the randyjensen RJ Quickcharts plugin up to and including version 0.6.1 are exposed. The vulnerability applies to all releases from the plugin’s initial release through 0.6.1.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while the EPSS of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation reports. An attacker would need to successfully insert malicious code into the plugin, but the mechanics of that injection are not documented in the CVE, so the exact attack pathway cannot be presumed at this time.
OpenCVE Enrichment
EUVD